← Back

Privacy Policy / Maxfiylik Siyosati

Platform: Style AI β€” AI-powered Virtual Stylist Platform

URL: https://app.style-ai.uz/

Effective date: 23 April 2026

Last updated: 23 April 2026

πŸ‡¬πŸ‡§

English Version

1. Who We Are

This platform ("Style AI", "we", "us", "our") is operated by Abrorbek Toshpolatov as a final-year academic project at the University of Wolverhampton (Module 6CS007 β€” Project and Professionalism). For all data-related queries, please contact: support@style-ai.uz.

2. What This Policy Covers

This Privacy Policy explains what personal data we collect when you use Style AI, why we collect it, how long we keep it, who we share it with, and what rights you have. It applies to all users of https://style-ai.uz/ and is published in compliance with the EU/UK General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and the Law of the Republic of Uzbekistan No. ZRU-547 "On Personal Data" (2019, as amended).

3. Who Can Use Style AI

Style AI is intended for users aged 18 and above. We do not knowingly collect personal data from children under 18. If you believe a minor has registered, please contact us immediately.

4. What Data We Collect

Data category Examples Why we need it
Account dataName, email, date of birth, gender, password (hashed), referral codeTo create and secure your account
Authentication dataGoogle OAuth identifier, optional secret word + hint, login attempts logTo authenticate you securely
Wardrobe dataClothing photographs you upload, category, season tagTo provide the styling service
Try-on dataBody photograph you upload for virtual try-on, AI-generated composite imageTo produce the try-on result
Payment dataPayment receipt image you uploadTo verify your top-up payment manually
Usage dataTry-on requests, AI calls, credit balance, audit logsTo operate the service and detect abuse
Technical dataIP address, browser, session cookiesTo deliver and secure the service

We do NOT collect: your card number, your bank details, biometric identifiers, or sensitive special-category data (health, religion, ethnicity, political views).

5. Why We Collect It (Lawful Basis)

  • Performance of contract β€” to deliver the styling, try-on, and payment-credit services you have requested.
  • Explicit consent β€” for sending body photographs to TheNewBlackAI for try-on processing. You can withdraw this consent at any time by deleting the request or your account.
  • Legitimate interest β€” for security monitoring, fraud prevention, and audit logging.
  • Legal obligation β€” where Uzbekistan or UK/EU law requires us to retain certain records.

6. How Long We Keep Your Data

Data Retention period
Clothing photographsWhile your account is active
Body photographs (in our storage)While your account is active
Body photographs (in TheNewBlackAI infrastructure)30 days, then automatically deleted by TheNewBlackAI
Payment receipts24 hours, then automatically deleted
Audit logs12 months
Account recordUntil you delete your account

When you click "Delete Account", we delete your account record, all uploaded images, and all associated try-on results within 1–5 minutes (depending on server load).

7. Who We Share Data With

We never sell your data. We share it only with the third parties listed below, and only the minimum data required for each function:

Third party What we share Purpose Location
TheNewBlackAIBody photograph + selected garment imageVirtual try-on generationEU/US
OpenAI (GPT-4o mini)Garment metadata (category, season, colour)Style commentary generationUS
Google (OAuth)Email + nameOptional sign-in methodUS/EU

We do not transfer your data to any other third party. We do not use your photographs to train any AI model, our own or anyone else's.

8. How We Protect Your Data (Security)

  • HTTPS / TLS 1.3 for all communication
  • bcrypt password hashing
  • Optional secret-word two-factor verification with hint and 5-attempt account lockout
  • CSRF tokens on every state-changing request
  • Eloquent ORM with parameterised queries (SQL-injection protection)
  • MIME and extension validation on all uploaded files
  • Files stored outside the public web root, accessible only through authenticated application routes
  • Rate limiting on upload and try-on endpoints
  • Audit logging of logins, uploads, and AI calls
  • Automatic deletion of payment receipts after 24 hours

9. Your Rights

Under GDPR, UK DPA 2018, and ZRU-547 you have the right to:

  • Access β€” request a copy of the personal data we hold about you
  • Rectification β€” correct inaccurate data
  • Erasure β€” delete your account and all associated data
  • Restriction β€” limit how we use your data
  • Portability β€” receive your data in a portable format
  • Object β€” object to processing based on legitimate interest
  • Withdraw consent β€” at any time, without affecting prior lawful processing

To exercise any of these rights, email support@style-ai.uz. We will respond within 30 days.

10. Cookies

We use only essential session cookies required to keep you logged in. We do not use advertising or tracking cookies.

11. Changes to This Policy

We may update this Privacy Policy. The latest version will always be available at https://style-ai.uz/privacy-policy and the "Last updated" date will reflect the change.

12. Complaints

If you believe we have mishandled your personal data, you can complain to:

  • Uzbekistan: the State Personalisation Centre under the Ministry of Digital Technologies
  • UK/EU users: the Information Commissioner's Office (ICO) at https://ico.org.uk/

πŸ‡ΊπŸ‡Ώ

O'zbek tilida

1. Biz kimmiz

Ushbu platforma ("Style AI", "biz") Abrorbek Toshpolatov tomonidan University of Wolverhampton'ning bitiruv loyihasi (Modul 6CS007 β€” Project and Professionalism) sifatida boshqariladi. Ma'lumotlar bo'yicha barcha savollar uchun: support@style-ai.uz.

2. Bu siyosat nimani qamrab oladi

Ushbu Maxfiylik siyosati Style AI'dan foydalanganingizda qaysi shaxsiy ma'lumotlaringizni yig'ishimiz, nima uchun yig'ishimiz, qancha vaqt saqlashimiz, kim bilan baham ko'rishimiz va sizning huquqlaringiz nima ekanligini tushuntiradi. U https://style-ai.uz/ ning barcha foydalanuvchilariga taalluqli va quyidagi qonunlar talablariga muvofiq nashr etilgan: GDPR (Yevropa Ittifoqi/Buyuk Britaniya), UK Data Protection Act 2018 va O'zbekiston Respublikasining "Shaxsga doir ma'lumotlar to'g'risida"gi ZRU-547 sonli Qonuni (2019, o'zgartishlar bilan).

3. Kim foydalana oladi

Style AI 18 yoshdan katta foydalanuvchilar uchun mo'ljallangan. Biz bilib turib 18 yoshgacha bo'lgan bolalardan ma'lumot yig'maymiz. Agar voyaga yetmagan ro'yxatdan o'tgan bo'lsa, darhol biz bilan bog'laning.

4. Qaysi ma'lumotlarni yig'amiz

Ma'lumot turi Misollar Nima uchun kerak
Akkaunt ma'lumotlariIsm, email, tug'ilgan sana, jinsi, parol (hash holatida), referral kodiAkkauntni yaratish va himoya qilish
AutentifikatsiyaGoogle OAuth ID, ixtiyoriy maxfiy so'z + maslahat, kirish urinishlari logiSizni xavfsiz kiritish
Garderob ma'lumotlariYuklangan kiyim rasmlari, kategoriya, mavsum tegiStylist xizmatini taqdim etish
Try-on ma'lumotlariYuklangan tana rasmi, AI tomonidan yaratilgan tasvirTry-on natijasini olish
To'lov ma'lumotlariSiz yuklagan to'lov chekiTo'lovni qo'lda tasdiqlash
FoydalanishTry-on so'rovlari, AI chaqiruvlari, kredit balansi, audit logXizmatni boshqarish va suiiste'molni aniqlash
TexnikIP-manzil, brauzer, sessiya cookie'lariXavfsiz xizmat ko'rsatish

Biz QABUL QILMAYMIZ: karta raqamingizni, bank ma'lumotlaringizni, biometrik identifikatorlarni, alohida toifadagi maxfiy ma'lumotlarni (sog'liq, din, etnik kelib chiqish, siyosiy qarashlar).

5. Qonuniy asoslar

  • Shartnoma ijrosi β€” siz so'ragan stylist, try-on va kredit xizmatlarini taqdim etish uchun.
  • Aniq rozilik β€” tana rasmini TheNewBlackAI'ga try-on uchun yuborish. Roziligingizni istalgan vaqtda qaytarib olishingiz mumkin.
  • Qonuniy manfaat β€” xavfsizlik monitoringi, firibgarlikni oldini olish, audit logging uchun.
  • Qonuniy majburiyat β€” O'zbekiston yoki UK/EU qonunchiligi talab qilganida.

6. Ma'lumotlarni qancha vaqt saqlaymiz

Ma'lumot Saqlash muddati
Kiyim rasmlariAkkaunt faol bo'lguncha
Tana rasmlari (bizning serverda)Akkaunt faol bo'lguncha
Tana rasmlari (TheNewBlackAI'da)30 kun, keyin avtomatik o'chiriladi
To'lov cheklari24 soat, keyin avtomatik o'chiriladi
Audit log12 oy
Akkaunt yozuviAkkauntni o'chirgancha

"Akkauntni o'chirish" tugmasini bosganingizda, akkaunt yozuvi, barcha rasmlar va try-on natijalari 1–5 daqiqa ichida (server yuklamasiga qarab) butunlay o'chiriladi.

7. Ma'lumotlarni kim bilan bo'lishamiz

Biz hech qachon sizning ma'lumotlaringizni sotmaymiz. Quyidagi uchinchi tomonlar bilan, faqat zarur minimal ma'lumotlar bilan bo'lishamiz:

Uchinchi tomon Yuboriladi Maqsad Joylashuv
TheNewBlackAITana rasmi + tanlangan kiyimVirtual try-on yaratishEU/US
OpenAI (GPT-4o mini)Kiyim metadatasiStyle izohi yaratishUS
Google (OAuth)Email + ismIxtiyoriy kirish usuliUS/EU

Boshqa hech qanday uchinchi tomonga yubormaymiz. Rasmlaringizni hech qanday AI modelni o'rgatish uchun ishlatmaymiz.

8. Ma'lumotlaringizni qanday himoya qilamiz

  • HTTPS / TLS 1.3 β€” barcha aloqa shifrlangan
  • bcrypt parol hashlash
  • Ixtiyoriy maxfiy so'z + maslahat + 5-urinish bloklash
  • CSRF tokenlar har bir yozish so'rovida
  • Eloquent ORM parametrli so'rovlar bilan (SQL injection himoyasi)
  • MIME va extension validatsiyasi har bir yuklamada
  • Fayllar ommaviy web root'dan tashqarida saqlanadi, faqat autentifikatsiya orqali kirish mumkin
  • Rate limiting upload va try-on endpoint'larida
  • Audit logging kirish, yuklash va AI chaqiruvlari
  • Avtomatik o'chirish to'lov cheklari uchun 24 soatdan keyin

9. Sizning huquqlaringiz

GDPR, UK DPA 2018 va ZRU-547 bo'yicha sizning huquqlaringiz:

  • Kirish β€” biz sizning haqingizda saqlayotgan ma'lumotlarning nusxasini so'rash
  • Tuzatish β€” noto'g'ri ma'lumotni tuzatish
  • O'chirish β€” akkauntni va barcha bog'liq ma'lumotlarni o'chirish
  • Cheklash β€” ma'lumotlardan foydalanishni cheklash
  • Ko'chirib o'tkazish β€” ma'lumotlaringizni ko'chiriladigan formatda olish
  • E'tiroz β€” qonuniy manfaatga asoslangan ishlovga e'tiroz bildirish
  • Rozilikni qaytarib olish β€” istalgan vaqtda

Huquqlarni amalga oshirish uchun support@style-ai.uz ga yozing. 30 kun ichida javob beramiz.

10. Cookie'lar

Faqat sessiyani saqlash uchun zarur cookie'larni ishlatamiz. Reklama yoki kuzatuv cookie'lari yo'q.

11. Siyosat o'zgarishlari

Maxfiylik siyosatini o'zgartirishimiz mumkin. Eng so'nggi versiya har doim https://style-ai.uz/privacy-policy sahifasida bo'ladi.

12. Shikoyatlar

Agar sizning ma'lumotlaringiz noto'g'ri ishlatilgan deb hisoblasangiz:

  • O'zbekiston: O'zbekiston Respublikasi Raqamli Texnologiyalar vazirligi huzuridagi Davlat Personifikatsiya Markazi
  • UK/EU foydalanuvchilari: Information Commissioner's Office (ICO) β€” https://ico.org.uk/